IP Library › Granted Patent US 12,562,890
Granted Patent B2
US 12,562,890 · App. 18/178,823 · Granted Feb 24, 2026

Method for exchanging cryptographic keys between communication subscribers

Inventors: Patrik Scheible (Stuttgart, DE); Sebastian Paul (Stuttgart, DE)
Assignee: ROBERT BOSCH GMBH
H04L9/085H04L9/0825H04L9/0852H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,562,890
App. No.
18/178,823
Granted
Feb 24, 2026
Kind
B2
Abstract

A method, in a server, for exchanging cryptographic keys for quantum-secure communication between the server and a client. The method includes: receiving a request message for a secure communication channel from a client, including at least one quantum-secure public ephemeral key and a first secret text; decapsulating the first secret text with a decapsulation function using a quantum-secure secret static key of the server, including generating a first secret; encapsulating the quantum-secure public ephemeral key with an encapsulation function including generating a second secret text and a second shared secret; encapsulating a quantum-secure public static key of the client using the encapsulation function, including generating a third secret text and a third shared secret; generating symmetric keys using at least the first, second, and third secrets; and sending a response message to the client, including the second and third secret texts.

Claims (57)

1 . A method, in a server, for exchanging cryptographic keys for quantum-secure communication between the server and a client, the method comprising the following steps:

receiving a request message for a secure communication channel from the client, wherein the request message includes at least one quantum-secure public ephemeral key and a first secret text, wherein the quantum-secure public ephemeral key is part of an asymmetric ephemeral key pair formed using a key generation function of a quantum-secure key encapsulation mechanism, wherein the request message forms a modified request message for an OpenSecureChannel handshake in an Open Platform Communications (OPC) Unified Architecture (UA) protocol;

decapsulating the first secret text with a decapsulation function of the quantum-secure key encapsulation mechanism using a quantum-secure secret static key of the server, wherein the decapsulation generates a first secret;

encapsulating the quantum-secure public ephemeral key with an encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a second secret text and a second shared secret;

encapsulating a quantum-secure public static key of the client using the encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a third secret text and a third shared secret;

generating hybrid symmetric keys using at least the first secret, the second secret, and the third secret; and

sending a response message to the client, wherein the response message includes at least the second secret text and the third secret text, wherein the response message forms a modified response message for an OpenSecureChannel handshake in an OPC UA protocol.

2 . The method according to claim 1 , further comprising:

forming a message authentication code (MAC) by applying a MAC function to a predetermined content of the response message using a key from the generated hybrid symmetric keys, wherein the response message additionally includes the formed MAC code.

3 . The method according to claim 1 , further comprising:

obtaining a message authentication code (MAC) in the request message from the client;

forming a local MAC code over a predetermined content of the request message using the decapsulated first secret as a key; and

comparing the formed local MAC code to the obtained MAC code to verify the obtained MAC code.

4 . The method according to claim 1 , wherein:

the request message further includes a first nonce;

the method further comprises generating a second nonce;

when generating the hybrid symmetric keys, the first nonce and the second nonce are additionally used; and

the response message to the client includes the second nonce.

5 . The method according to claim 4 , wherein the generation of the hybrid symmetric keys includes:

generating a third nonce and a fourth nonce using the first secret, the second secret, and the third secret; and

generating the hybrid symmetric keys from the first nonce, the second nonce, the third nonce, and the fourth nonce using a combiner.

6 . The method according to claim 5 , wherein the server and the client use the same quantum-secure key encapsulation mechanism and the same combiner.

7 . A method, in a client, for exchanging cryptographic keys for quantum-secure communication between the client and a server, the method comprising the following steps:

forming, using a key generation function of a quantum-secure key encapsulation mechanism, an asymmetric quantum-secure ephemeral key pair with a quantum-secure public ephemeral key and a quantum-secure secret ephemeral key;

encapsulating the quantum-secure public ephemeral key using an encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a first secret text and a first shared secret;

sending a request message to the server, the request message including at least the quantum-secure public ephemeral key and the first secret text, wherein the request message forms a modified request message for an OpenSecureChannel handshake in an Open Platform Communications (OPC) Unified Architecture (UA) protocol;

receiving, from the server, a response message including at least a second secret text and a third secret text, wherein the response message forms a modified response message for an OpenSecureChannel handshake in an OPC UA protocol;

decapsulating the received second secret text with a decapsulation function of the quantum-secure key encapsulation mechanism using the secret quantum-secure ephemeral key, wherein the decapsulation yields a second shared secret;

decapsulating the received third secret text with a decapsulation function of the quantum-secure key encapsulation mechanism using a secret quantum-secure static key of the client, wherein the decapsulation yields a third shared secret; and

generating hybrid symmetric keys using at least the first secret, the second secret and the third secret.

8 . The method according to claim 7 , further comprising:

forming a message authentication code (MAC) by applying a MAC function to a predetermined content of the request message using the first secret as a key;

wherein the request message to the server additionally includes the formed MAC code.

9 . The method according to claim 7 , further comprising:

obtaining a message authentication code (MAC) in the response message from the server;

forming a local MAC code over a predetermined content of the response message using a predetermined key from the generated hybrid symmetric keys; and

comparing the formed local MAC code to the obtained MAC code to verify the obtained MAC code.

10 . The method according to claim 7 , wherein the method further comprises generating a first nonce, and wherein the request message to the server additionally includes the first nonce, wherein the response message from the server additionally includes a second nonce, and wherein when generating the hybrid symmetric keys, the first nonce and the second nonce are additionally used.

11 . The method according to claim 7 , wherein the hybrid symmetric keys are used to encrypt and/or sign messages in a subsequent secure communication session between the server and the client.

12 . The method according to claim 7 , wherein the request message and/or the response message is encrypted and/or signed using asymmetric key pairs, and wherein the method further comprises: (i) decrypting the request message and/or the response message, and/or (ii) verifying a signature of the request message and/or the response message.

13 . The method according to claim 10 wherein the generation of the hybrid symmetric keys includes: generating a third nonce and a fourth nonce using the first secret, the second secret, and the third secret; and generating the hybrid symmetric keys from the first nonce, the second nonce, the third nonce, and the fourth nonce using a combiner.

14 . The method according to claim 13 , wherein the combiner is an XOR combiner.

15 . The method according to claim 13 , wherein the server and the client use the same quantum-secure key encapsulation mechanism and the same combiner.

16 . A computing unit, in a server, configured to exchange cryptographic keys for quantum-secure communication between the server and a client, the computing unit comprising a processor configured to:

receive a request message for a secure communication channel from the client, wherein the request message includes at least one quantum-secure public ephemeral key and a first secret text, wherein the quantum-secure public ephemeral key is part of an asymmetric ephemeral key pair formed using a key generation function of a quantum-secure key encapsulation mechanism, wherein the request message forms a modified request message for an OpenSecureChannel handshake in an Open Platform Communications (OPC) Unified Architecture (UA) protocol;

decapsulate the first secret text with a decapsulation function of the quantum-secure key encapsulation mechanism using a quantum-secure secret static key of the server, wherein the decapsulation generates a first secret;

encapsulate the quantum-secure public ephemeral key with an encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a second secret text and a second shared secret;

encapsulate a quantum-secure public static key of the client using the encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a third secret text and a third shared secret;

generate hybrid symmetric keys using at least the first secret, the second secret, and the third secret; and

send a response message to the client, wherein the response message includes at least the second secret text and the third secret text, wherein the response message forms a modified response message for an OpenSecureChannel handshake in an OPC UA protocol.

17 . A non-transitory machine-readable storage medium on which is stored a computer program for exchanging cryptographic keys for quantum-secure communication between a server and a client, the computer program, when executed by a computing unit of the server, causing the computing unit to perform the following steps:

receiving a request message for a secure communication channel from the client, wherein the request message includes at least one quantum-secure public ephemeral key and a first secret text, wherein the quantum-secure public ephemeral key is part of an asymmetric ephemeral key pair formed using a key generation function of a quantum-secure key encapsulation mechanism, wherein the request message forms a modified request message for an OpenSecureChannel handshake in an Open Platform Communications (OPC) Unified Architecture (UA) protocol;

decapsulating the first secret text with a decapsulation function of the quantum-secure key encapsulation mechanism using a quantum-secure secret static key of the server, wherein the decapsulation generates a first secret;

encapsulating the quantum-secure public ephemeral key with an encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a second secret text and a second shared secret;

encapsulating a quantum-secure public static key of the client using the encapsulation function of the quantum-secure key encapsulation mechanism, wherein the encapsulation generates a third secret text and a third shared secret;

generating hybrid symmetric keys using at least the first secret, the second secret, and the third secret; and

sending a response message to the client, wherein the response message includes at least the second secret text and the third secret text, wherein the response message forms a modified response message for an OpenSecureChannel handshake in an OPC UA protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: SCHEIBLE, PATRIK; PAUL, SEBASTIAN
To: ROBERT BOSCH GMBH
Reel/Frame 064211/0189 →
Priority Claims (1)
DE 10 2022 203 725.1 · Apr 13, 2022 · national
Continuity (1)
Related Publication 20230336334A1 · Oct 19, 2023
References Cited (7)
US 20220006835A1 · Gray et al. · 2022 [cited by applicant]
US 20240106636A1 · Nix · 2024 [cited by examiner]
CN 108111301A · 2018 [cited by applicant]
DE 102020200726A1 · 2021 [cited by applicant]
EP 4221070A1 · 2023 [cited by examiner]
EP 4465588A1 · 2024 [cited by examiner]
WO 2022067132A1 · 2022 [cited by applicant]